How to block a complete AS (autonomous system)
-
After reading the article on
http://www.theregister.co.uk/2010/11/18/zeroaccess_rootkit_deconstructed/
http://resources.infosecinstitute.com/zeroaccess-malware-part-4-tracing-the-crimeware-origins-by-reversing-injected-code/I wanted to block the AS AS29073 which belongs to Ecatel Network which is a well known crimeware friendly ISP to avoid a lot of trouble for my users.
I could of course put a firewall rule in place blocking 94.102.60.0/24 but blocking the whole AS would be nicer.
Is that somehow possible or should I investigate installing snort or another additional package ?
My setup is a single pfsense 1.2.3 box with a GEODE CPU from applianceshop.eu , connected to a single broadband WAN connection
thanks,
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.